Improper Certificate Validation Affecting icinga/icinga2 package, versions [2.5.0,2.11.10)[2.12.0,2.12.6)[2.13.0,2.13.1)


Severity

Recommended
0.0
high
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.27% (68th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-ICINGAICINGA2-2365028
  • published26 Jan 2022
  • disclosed19 Aug 2021
  • creditUnknown

Introduced: 19 Aug 2021

CVE-2021-37698  (opens in a new tab)
CWE-295  (opens in a new tab)

How to fix?

Upgrade icinga/icinga2 to version 2.11.10, 2.12.6, 2.13.1 or higher.

Overview

Affected versions of this package are vulnerable to Improper Certificate Validation. Icinga is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting. In versions 2.5.0 through 2.13.0, ElasticsearchWriter, GelfWriter, InfluxdbWriter and Influxdb2Writer do not verify the server's certificate despite a certificate authority being specified. Icinga 2 instances which connect to any of the mentioned time series databases (TSDBs) using TLS over a spoofable infrastructure should immediately upgrade to version 2.13.1, 2.12.6, or 2.11.11 to patch the issue. Such instances should also change the credentials (if any) used by the TSDB writer feature to authenticate against the TSDB. There are no workarounds aside from upgrading.

CVSS Scores

version 3.1